Investigating an action
Find out who carried out an action in the Console, when it happened, which object was affected, and what the outcome was.
When to use this
- Use it when a rule, user, group, or account changed unexpectedly.
- Use it when you need to evidence a change for an audit.
- Use it when a team questions why an access changed.
Before you start
- Have an approximate time window.
- Know which object was affected — a user, group, rule, or account.
- Have a role that lets you view the audit trail.
Step by step
- Open Audit Center.
- Filter by period.
- Add filters by person or object where you know them.
- Open the candidate records.
- Compare the time, the outcome, and the action's description.
- Export the evidence if you need to attach it to a process.
What happens next
- You will be able to explain the action based on the product's evidence.
- If the action was improper, an administrator can correct the access.
- The investigation may point to a need to review groups or rules.
Common errors
- Using the wrong period: the action may fall outside the results.
- Confusing similar actions: read the details before concluding.
- Overlooking earlier actions that set the change up.
Good practice
- Work with a timeline.
- Keep the filters used in the investigation.
- Review who is responsible for sensitive actions after incidents.
Next steps
Was this page helpful?
Report a problem on this pageDo not send passwords, keys, tokens, or customer data.